Vulnerabilities · 104 days ago

Old Rockwell Trust Flaw Is Still the Real Risk

Rockwell’s latest patch set matters, but the operational problem is the older, already-exploited trust path that is still sitting in deployed OT gear. The company confirmed in-the-wild abuse of CVE-2021-22681, even as its new advisories for Logix, CompactLogix, ControlLogix, Flex I/O, RSLinx, and FactoryTalk have not yet been seen targeted.

The new fixes cover DoS bugs in controllers, authentication-bypass and password-change issues in FactoryTalk Historian Site Edition and Flex I/O dual-port Ethernet/IP adapters, and an improper API authorization flaw in FactoryTalk Analytics PavilionX. For plant and critical-infrastructure teams, the sharper risk is still legacy engineering and controller assets that trust device identity or session state and may be exposed through a path attackers already know works.

CVE-2021-22681

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a… EPSS 64% (99th percentile).

CISA federal remediation date Mar 26 · date passed

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-06-18

Editions

Related stories